redhatopenshift.azure.com/v20260901preview

APIVersion

Value Description
“2026-09-01-preview”

HcpOpenShiftCluster

Generator information:

  • Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
  • ARM URI: /​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.RedHatOpenShift/​hcpOpenShiftClusters/​{hcpOpenShiftClusterName}

Used by: HcpOpenShiftClusterList.

Property Description Type
metav1.TypeMeta
metav1.ObjectMeta
spec HcpOpenShiftCluster_Spec
Optional
status HcpOpenShiftCluster_STATUS
Optional

HcpOpenShiftCluster_Spec

Property Description Type
azureName The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity
Optional
location The geo-location where the resource lives string
Required
operatorSpec The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure HcpOpenShiftClusterOperatorSpec
Optional
owner The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a resources.azure.com/ResourceGroup resource genruntime.KnownResourceReference
Required
properties The resource-specific properties for this resource. HcpOpenShiftClusterProperties
Optional
tags Resource tags. map[string]string
Optional

HcpOpenShiftCluster_STATUS

Property Description Type
conditions The observed state of the resource conditions.Condition[]
Optional
id Fully qualified resource ID for the resource. E.g. “/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​{resourceProviderNamespace}/​{resourceType}/​{resourceName}” string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity_STATUS
Optional
location The geo-location where the resource lives string
Optional
name The name of the resource string
Optional
properties The resource-specific properties for this resource. HcpOpenShiftClusterProperties_STATUS
Optional
systemData Azure Resource Manager metadata containing createdBy and modifiedBy information. SystemData_STATUS
Optional
tags Resource tags. map[string]string
Optional
type The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” string
Optional

HcpOpenShiftClusterList

Generator information:

  • Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
  • ARM URI: /​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.RedHatOpenShift/​hcpOpenShiftClusters/​{hcpOpenShiftClusterName}
Property Description Type
metav1.TypeMeta
metav1.ListMeta
items HcpOpenShiftCluster[]
Optional

HcpOpenShiftClustersExternalAuth

Generator information:

  • Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
  • ARM URI: /​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.RedHatOpenShift/​hcpOpenShiftClusters/​{hcpOpenShiftClusterName}/​externalAuths/​{externalAuthName}

Used by: HcpOpenShiftClustersExternalAuthList.

Property Description Type
metav1.TypeMeta
metav1.ObjectMeta
spec HcpOpenShiftClustersExternalAuth_Spec
Optional
status HcpOpenShiftClustersExternalAuth_STATUS
Optional

HcpOpenShiftClustersExternalAuth_Spec

Property Description Type
azureName The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. string
Optional
operatorSpec The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure HcpOpenShiftClustersExternalAuthOperatorSpec
Optional
owner The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource genruntime.KnownResourceReference
Required
properties The resource-specific properties for this resource. ExternalAuthProperties
Optional

HcpOpenShiftClustersExternalAuth_STATUS

Property Description Type
conditions The observed state of the resource conditions.Condition[]
Optional
id Fully qualified resource ID for the resource. E.g. “/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​{resourceProviderNamespace}/​{resourceType}/​{resourceName}” string
Optional
name The name of the resource string
Optional
properties The resource-specific properties for this resource. ExternalAuthProperties_STATUS
Optional
systemData Azure Resource Manager metadata containing createdBy and modifiedBy information. SystemData_STATUS
Optional
type The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” string
Optional

HcpOpenShiftClustersExternalAuthList

Generator information:

  • Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
  • ARM URI: /​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.RedHatOpenShift/​hcpOpenShiftClusters/​{hcpOpenShiftClusterName}/​externalAuths/​{externalAuthName}
Property Description Type
metav1.TypeMeta
metav1.ListMeta
items HcpOpenShiftClustersExternalAuth[]
Optional

HcpOpenShiftClustersNodePool

Generator information:

  • Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
  • ARM URI: /​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.RedHatOpenShift/​hcpOpenShiftClusters/​{hcpOpenShiftClusterName}/​nodePools/​{nodePoolName}

Used by: HcpOpenShiftClustersNodePoolList.

Property Description Type
metav1.TypeMeta
metav1.ObjectMeta
spec HcpOpenShiftClustersNodePool_Spec
Optional
status HcpOpenShiftClustersNodePool_STATUS
Optional

HcpOpenShiftClustersNodePool_Spec

Property Description Type
azureName The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity
Optional
location The geo-location where the resource lives string
Required
operatorSpec The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure HcpOpenShiftClustersNodePoolOperatorSpec
Optional
owner The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource genruntime.KnownResourceReference
Required
properties The resource-specific properties for this resource. NodePoolProperties
Optional
tags Resource tags. map[string]string
Optional

HcpOpenShiftClustersNodePool_STATUS

Property Description Type
conditions The observed state of the resource conditions.Condition[]
Optional
id Fully qualified resource ID for the resource. E.g. “/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​{resourceProviderNamespace}/​{resourceType}/​{resourceName}” string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity_STATUS
Optional
location The geo-location where the resource lives string
Optional
name The name of the resource string
Optional
properties The resource-specific properties for this resource. NodePoolProperties_STATUS
Optional
systemData Azure Resource Manager metadata containing createdBy and modifiedBy information. SystemData_STATUS
Optional
tags Resource tags. map[string]string
Optional
type The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” string
Optional

HcpOpenShiftClustersNodePoolList

Generator information:

  • Generated from: /redhatopenshift/resource-manager/Microsoft.RedHatOpenShift/hcpopenshiftclusters/preview/2026-09-01-preview/openapi.json
  • ARM URI: /​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.RedHatOpenShift/​hcpOpenShiftClusters/​{hcpOpenShiftClusterName}/​nodePools/​{nodePoolName}
Property Description Type
metav1.TypeMeta
metav1.ListMeta
items HcpOpenShiftClustersNodePool[]
Optional

HcpOpenShiftCluster_Spec

Used by: HcpOpenShiftCluster.

Property Description Type
azureName The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity
Optional
location The geo-location where the resource lives string
Required
operatorSpec The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure HcpOpenShiftClusterOperatorSpec
Optional
owner The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a resources.azure.com/ResourceGroup resource genruntime.KnownResourceReference
Required
properties The resource-specific properties for this resource. HcpOpenShiftClusterProperties
Optional
tags Resource tags. map[string]string
Optional

HcpOpenShiftCluster_STATUS

HCP cluster resource

Used by: HcpOpenShiftCluster.

Property Description Type
conditions The observed state of the resource conditions.Condition[]
Optional
id Fully qualified resource ID for the resource. E.g. “/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​{resourceProviderNamespace}/​{resourceType}/​{resourceName}” string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity_STATUS
Optional
location The geo-location where the resource lives string
Optional
name The name of the resource string
Optional
properties The resource-specific properties for this resource. HcpOpenShiftClusterProperties_STATUS
Optional
systemData Azure Resource Manager metadata containing createdBy and modifiedBy information. SystemData_STATUS
Optional
tags Resource tags. map[string]string
Optional
type The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” string
Optional

HcpOpenShiftClustersExternalAuth_Spec

Used by: HcpOpenShiftClustersExternalAuth.

Property Description Type
azureName The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. string
Optional
operatorSpec The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure HcpOpenShiftClustersExternalAuthOperatorSpec
Optional
owner The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource genruntime.KnownResourceReference
Required
properties The resource-specific properties for this resource. ExternalAuthProperties
Optional

HcpOpenShiftClustersExternalAuth_STATUS

Used by: HcpOpenShiftClustersExternalAuth.

Property Description Type
conditions The observed state of the resource conditions.Condition[]
Optional
id Fully qualified resource ID for the resource. E.g. “/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​{resourceProviderNamespace}/​{resourceType}/​{resourceName}” string
Optional
name The name of the resource string
Optional
properties The resource-specific properties for this resource. ExternalAuthProperties_STATUS
Optional
systemData Azure Resource Manager metadata containing createdBy and modifiedBy information. SystemData_STATUS
Optional
type The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” string
Optional

HcpOpenShiftClustersNodePool_Spec

Used by: HcpOpenShiftClustersNodePool.

Property Description Type
azureName The name of the resource in Azure. This is often the same as the name of the resource in Kubernetes but it doesn’t have to be. string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity
Optional
location The geo-location where the resource lives string
Required
operatorSpec The specification for configuring operator behavior. This field is interpreted by the operator and not passed directly to Azure HcpOpenShiftClustersNodePoolOperatorSpec
Optional
owner The owner of the resource. The owner controls where the resource goes when it is deployed. The owner also controls the resources lifecycle. When the owner is deleted the resource will also be deleted. Owner is expected to be a reference to a redhatopenshift.azure.com/HcpOpenShiftCluster resource genruntime.KnownResourceReference
Required
properties The resource-specific properties for this resource. NodePoolProperties
Optional
tags Resource tags. map[string]string
Optional

HcpOpenShiftClustersNodePool_STATUS

Used by: HcpOpenShiftClustersNodePool.

Property Description Type
conditions The observed state of the resource conditions.Condition[]
Optional
id Fully qualified resource ID for the resource. E.g. “/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​{resourceProviderNamespace}/​{resourceType}/​{resourceName}” string
Optional
identity The managed service identities assigned to this resource. ManagedServiceIdentity_STATUS
Optional
location The geo-location where the resource lives string
Optional
name The name of the resource string
Optional
properties The resource-specific properties for this resource. NodePoolProperties_STATUS
Optional
systemData Azure Resource Manager metadata containing createdBy and modifiedBy information. SystemData_STATUS
Optional
tags Resource tags. map[string]string
Optional
type The type of the resource. E.g. “Microsoft.Compute/virtualMachines” or “Microsoft.Storage/storageAccounts” string
Optional

ExternalAuthProperties

External Auth profile

Used by: HcpOpenShiftClustersExternalAuth_Spec.

Property Description Type
claim External Auth claim This configures how claims are validated and applied. ExternalAuthClaimProfile
Required
clients External Auth OIDC clients There must not be more than 20 entries and entries must have unique namespace/name pairs. ExternalAuthClientProfile[]
Optional
issuer Token Issuer profile TokenIssuerProfile
Required

ExternalAuthProperties_STATUS

External Auth profile

Used by: HcpOpenShiftClustersExternalAuth_STATUS.

Property Description Type
claim External Auth claim This configures how claims are validated and applied. ExternalAuthClaimProfile_STATUS
Optional
clients External Auth OIDC clients There must not be more than 20 entries and entries must have unique namespace/name pairs. ExternalAuthClientProfile_STATUS[]
Optional
issuer Token Issuer profile TokenIssuerProfile_STATUS
Optional
provisioningState Provisioning state ExternalAuthProvisioningState_STATUS
Optional
status Status of the external auth resource ResourceStatus_STATUS
Optional

HcpOpenShiftClusterOperatorSpec

Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure

Used by: HcpOpenShiftCluster_Spec.

Property Description Type
configMapExpressions configures where to place operator written dynamic ConfigMaps (created with CEL expressions). core.DestinationExpression[]
Optional
secretExpressions configures where to place operator written dynamic secrets (created with CEL expressions). core.DestinationExpression[]
Optional
secrets configures where to place Azure generated secrets. HcpOpenShiftClusterOperatorSecrets
Optional

HcpOpenShiftClusterProperties

HCP cluster properties

Used by: HcpOpenShiftCluster_Spec.

Property Description Type
api Shows the cluster API server profile ApiProfile
Optional
autoscaling Configure ClusterAutoscaling . ClusterAutoscalingProfile
Optional
clusterImageRegistry OpenShift internal image registry ClusterImageRegistryProfile
Optional
cryptoRestrictions Cryptographic restrictions for kernel and userspace libraries HcpOpenShiftClusterProperties_CryptoRestrictions
Optional
dns Cluster DNS configuration DnsProfile
Optional
etcd Configure ETCD. EtcdProfile
Optional
imageDigestMirrors imageDigestMirrors is a set of rules to allow pulling images from a mirrored registry by using digest specifications. WARNING: Updating this array will redeploy all node pools in the cluster. ImageDigestMirror[]
Optional
ingress The cluster ingress configuration IngressProfile
Optional
network Cluster network configuration NetworkProfile
Optional
nodeDrainTimeoutMinutes nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are in minutes and from 0 to 10080 minutes (1 week). 0 means that the MachinePool can be drained without any time limitation. This is the value is used a default for all NodePools. It can be overridden by specifying nodeDrainTimeoutMinutes for a given NodePool int
Optional
platform Azure platform configuration PlatformProfile
Required
version Version of the control plane components VersionProfile
Required

HcpOpenShiftClusterProperties_STATUS

HCP cluster properties

Used by: HcpOpenShiftCluster_STATUS.

Property Description Type
api Shows the cluster API server profile ApiProfile_STATUS
Optional
autoscaling Configure ClusterAutoscaling . ClusterAutoscalingProfile_STATUS
Optional
clusterImageRegistry OpenShift internal image registry ClusterImageRegistryProfile_STATUS
Optional
console Shows the cluster web console information ConsoleProfile_STATUS
Optional
cryptoRestrictions Cryptographic restrictions for kernel and userspace libraries HcpOpenShiftClusterProperties_CryptoRestrictions_STATUS
Optional
dns Cluster DNS configuration DnsProfile_STATUS
Optional
etcd Configure ETCD. EtcdProfile_STATUS
Optional
imageDigestMirrors imageDigestMirrors is a set of rules to allow pulling images from a mirrored registry by using digest specifications. WARNING: Updating this array will redeploy all node pools in the cluster. ImageDigestMirror_STATUS[]
Optional
ingress The cluster ingress configuration IngressProfile_STATUS
Optional
network Cluster network configuration NetworkProfile_STATUS
Optional
nodeDrainTimeoutMinutes nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are in minutes and from 0 to 10080 minutes (1 week). 0 means that the MachinePool can be drained without any time limitation. This is the value is used a default for all NodePools. It can be overridden by specifying nodeDrainTimeoutMinutes for a given NodePool int
Optional
platform Azure platform configuration PlatformProfile_STATUS
Optional
provisioningState The status of the last operation. ProvisioningState_STATUS
Optional
status Status of the cluster resource ResourceStatus_STATUS
Optional
version Version of the control plane components VersionProfile_STATUS
Optional

HcpOpenShiftClustersExternalAuthOperatorSpec

Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure

Used by: HcpOpenShiftClustersExternalAuth_Spec.

Property Description Type
configMapExpressions configures where to place operator written dynamic ConfigMaps (created with CEL expressions). core.DestinationExpression[]
Optional
secretExpressions configures where to place operator written dynamic secrets (created with CEL expressions). core.DestinationExpression[]
Optional

HcpOpenShiftClustersNodePoolOperatorSpec

Details for configuring operator behavior. Fields in this struct are interpreted by the operator directly rather than being passed to Azure

Used by: HcpOpenShiftClustersNodePool_Spec.

Property Description Type
configMapExpressions configures where to place operator written dynamic ConfigMaps (created with CEL expressions). core.DestinationExpression[]
Optional
secretExpressions configures where to place operator written dynamic secrets (created with CEL expressions). core.DestinationExpression[]
Optional

ManagedServiceIdentity

Managed service identity (system assigned and/or user assigned identities)

Used by: HcpOpenShiftCluster_Spec, and HcpOpenShiftClustersNodePool_Spec.

Property Description Type
type Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed). ManagedServiceIdentityType
Required
userAssignedIdentities The set of user assigned identities associated with the resource. The userAssignedIdentities dictionary keys will be ARM resource ids in the form: ‘/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.ManagedIdentity/​userAssignedIdentities/​{identityName}. The dictionary values can be empty objects ({}) in requests. UserAssignedIdentityDetails[]
Optional

ManagedServiceIdentity_STATUS

Managed service identity (system assigned and/or user assigned identities)

Used by: HcpOpenShiftCluster_STATUS, and HcpOpenShiftClustersNodePool_STATUS.

Property Description Type
principalId The service principal ID of the system assigned identity. This property will only be provided for a system assigned identity. string
Optional
tenantId The tenant ID of the system assigned identity. This property will only be provided for a system assigned identity. string
Optional
type Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed). ManagedServiceIdentityType_STATUS
Optional
userAssignedIdentities The set of user assigned identities associated with the resource. The userAssignedIdentities dictionary keys will be ARM resource ids in the form: ‘/​subscriptions/​{subscriptionId}/​resourceGroups/​{resourceGroupName}/​providers/​Microsoft.ManagedIdentity/​userAssignedIdentities/​{identityName}. The dictionary values can be empty objects ({}) in requests. map[string]UserAssignedIdentity_STATUS
Optional

NodePoolProperties

Represents the node pool properties

Used by: HcpOpenShiftClustersNodePool_Spec.

Property Description Type
autoRepair Auto-repair bool
Optional
autoScaling Representation of a autoscaling in a node pool. NodePoolAutoScaling
Optional
labels Kubernetes labels to propagate to the NodePool Nodes Note that when the labels are updated this is only applied to newly create nodes in the Nodepool, existing node labels remain unchanged. Label[]
Optional
nodeDrainTimeoutMinutes nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are from 0 to 10080 minutes (1 week) . 0 means that the NodePool can be drained without any time limitation. If unset the cluster nodeDrainTimeoutMinutes value is used as a default. int
Optional
platform Azure node pool platform configuration NodePoolPlatformProfile
Required
replicas The number of worker nodes, it cannot be used together with autoscaling. Validation:
  • Minimum: 0
  • Maximum: 200 (only when availabilityZone is not specified)
  • No maximum when availabilityZone is specified| int
    Optional| | taints| Taints for the nodes| Taint[]
    Optional| | version| OpenShift version for the nodepool| NodePoolVersionProfile
    Optional|

NodePoolProperties_STATUS

Represents the node pool properties

Used by: HcpOpenShiftClustersNodePool_STATUS.

Property Description Type
autoRepair Auto-repair bool
Optional
autoScaling Representation of a autoscaling in a node pool. NodePoolAutoScaling_STATUS
Optional
labels Kubernetes labels to propagate to the NodePool Nodes Note that when the labels are updated this is only applied to newly create nodes in the Nodepool, existing node labels remain unchanged. Label_STATUS[]
Optional
nodeDrainTimeoutMinutes nodeDrainTimeoutMinutes is the grace period for how long Pod Disruption Budget-protected workloads will be respected during any node draining operation. After this grace period, any workloads protected by Pod Disruption Budgets that have not been successfully drained from a node will be forcibly evicted. This is especially relevant to cluster upgrades. Valid values are from 0 to 10080 minutes (1 week) . 0 means that the NodePool can be drained without any time limitation. If unset the cluster nodeDrainTimeoutMinutes value is used as a default. int
Optional
platform Azure node pool platform configuration NodePoolPlatformProfile_STATUS
Optional
provisioningState Provisioning state ProvisioningState_STATUS
Optional
replicas The number of worker nodes, it cannot be used together with autoscaling. Validation:
  • Minimum: 0
  • Maximum: 200 (only when availabilityZone is not specified)
  • No maximum when availabilityZone is specified| int
    Optional| | status| Status of the node pool resource| ResourceStatus_STATUS
    Optional| | taints| Taints for the nodes| Taint_STATUS[]
    Optional| | version| OpenShift version for the nodepool| NodePoolVersionProfile_STATUS
    Optional|

SystemData_STATUS

Metadata pertaining to creation and last modification of the resource.

Used by: HcpOpenShiftCluster_STATUS, HcpOpenShiftClustersExternalAuth_STATUS, and HcpOpenShiftClustersNodePool_STATUS.

Property Description Type
createdAt The timestamp of resource creation (UTC). string
Optional
createdBy The identity that created the resource. string
Optional
createdByType The type of identity that created the resource. SystemData_CreatedByType_STATUS
Optional
lastModifiedAt The timestamp of resource last modification (UTC) string
Optional
lastModifiedBy The identity that last modified the resource. string
Optional
lastModifiedByType The type of identity that last modified the resource. SystemData_LastModifiedByType_STATUS
Optional

ApiProfile

Information about the API of a cluster.

Used by: HcpOpenShiftClusterProperties.

Property Description Type
authorizedCidrs The list of authorized IPv4 CIDR blocks allowed to access the API server. Maximum 500 entries. string[]
Optional
visibility The internet visibility of the OpenShift API server ApiProfile_Visibility
Optional

ApiProfile_STATUS

Information about the API of a cluster.

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
authorizedCidrs The list of authorized IPv4 CIDR blocks allowed to access the API server. Maximum 500 entries. string[]
Optional
url URL endpoint for the API server string
Optional
visibility The internet visibility of the OpenShift API server ApiProfile_Visibility_STATUS
Optional

ClusterAutoscalingProfile

ClusterAutoscaling specifies auto-scaling behavior that applies to all NodePools associated with a control plane.

Used by: HcpOpenShiftClusterProperties.

Property Description Type
maxNodeProvisionTimeSeconds maxNodeProvisionTimeSeconds is the maximum time to wait for node provisioning before considering the provisioning to be unsuccessful. The default is 900 seconds, or 15 minutes. int
Optional
maxNodesTotal maxNodesTotal is the maximum allowable number of nodes for the Autoscaler scale out to be operational. The autoscaler will not grow the cluster beyond this number. If omitted, the autoscaler will not have a maximum limit. int
Optional
maxPodGracePeriodSeconds maxPodGracePeriod is the maximum seconds to wait for graceful pod termination before scaling down a NodePool. The default is 600 seconds. int
Optional
podPriorityThreshold podPriorityThreshold enables users to schedule “best-effort” pods, which shouldn’t trigger autoscaler actions, but only run when there are spare resources available. The default is -10. See the following for more details: https://github.com/kubernetes/autoscaler/blob/master/cluster-autoscaler/FAQ.md#how-does-cluster-autoscaler-work-with-pod-priority-and-preemption int
Optional

ClusterAutoscalingProfile_STATUS

ClusterAutoscaling specifies auto-scaling behavior that applies to all NodePools associated with a control plane.

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
maxNodeProvisionTimeSeconds maxNodeProvisionTimeSeconds is the maximum time to wait for node provisioning before considering the provisioning to be unsuccessful. The default is 900 seconds, or 15 minutes. int
Optional
maxNodesTotal maxNodesTotal is the maximum allowable number of nodes for the Autoscaler scale out to be operational. The autoscaler will not grow the cluster beyond this number. If omitted, the autoscaler will not have a maximum limit. int
Optional
maxPodGracePeriodSeconds maxPodGracePeriod is the maximum seconds to wait for graceful pod termination before scaling down a NodePool. The default is 600 seconds. int
Optional
podPriorityThreshold podPriorityThreshold enables users to schedule “best-effort” pods, which shouldn’t trigger autoscaler actions, but only run when there are spare resources available. The default is -10. See the following for more details: https://github.com/kubernetes/autoscaler/blob/master/cluster-autoscaler/FAQ.md#how-does-cluster-autoscaler-work-with-pod-priority-and-preemption int
Optional

ClusterImageRegistryProfile

OpenShift cluster image registry

Used by: HcpOpenShiftClusterProperties.

Property Description Type
state state indicates the desired ImageStream-backed cluster image registry installation mode. This can only be set during cluster creation and cannot be changed after cluster creation. Enabled means the ImageStream-backed image registry will be run as pods on worker nodes in the cluster. Disabled means the ImageStream-backed image registry will not be present in the cluster. The default is Enabled. ClusterImageRegistryProfile_State
Optional

ClusterImageRegistryProfile_STATUS

OpenShift cluster image registry

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
state state indicates the desired ImageStream-backed cluster image registry installation mode. This can only be set during cluster creation and cannot be changed after cluster creation. Enabled means the ImageStream-backed image registry will be run as pods on worker nodes in the cluster. Disabled means the ImageStream-backed image registry will not be present in the cluster. The default is Enabled. ClusterImageRegistryProfile_State_STATUS
Optional

ConsoleProfile_STATUS

Configuration of the cluster web console

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
url The cluster web console URL endpoint string
Optional

DnsProfile

DNS contains the DNS settings of the cluster

Used by: HcpOpenShiftClusterProperties.

Property Description Type
baseDomainPrefix BaseDomainPrefix is the unique name of the cluster representing the OpenShift’s cluster name. BaseDomainPrefix is the name that will appear in the cluster’s DNS, provisioned cloud providers resources string
Optional

DnsProfile_STATUS

DNS contains the DNS settings of the cluster

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
baseDomain BaseDomain is the base DNS domain of the cluster. string
Optional
baseDomainPrefix BaseDomainPrefix is the unique name of the cluster representing the OpenShift’s cluster name. BaseDomainPrefix is the name that will appear in the cluster’s DNS, provisioned cloud providers resources string
Optional

EtcdProfile

The ETCD settings and configuration options.

Used by: HcpOpenShiftClusterProperties.

Property Description Type
dataEncryption ETCD Data Encryption settings. If not specified platform managed keys are used. EtcdDataEncryptionProfile
Optional

EtcdProfile_STATUS

The ETCD settings and configuration options.

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
dataEncryption ETCD Data Encryption settings. If not specified platform managed keys are used. EtcdDataEncryptionProfile_STATUS
Optional

ExternalAuthClaimProfile

External Auth claim profile

Used by: ExternalAuthProperties.

Property Description Type
mappings The claim mappings TokenClaimMappingsProfile
Required
validationRules The claim validation rules TokenClaimValidationRule[]
Optional

ExternalAuthClaimProfile_STATUS

External Auth claim profile

Used by: ExternalAuthProperties_STATUS.

Property Description Type
mappings The claim mappings TokenClaimMappingsProfile_STATUS
Optional
validationRules The claim validation rules TokenClaimValidationRule_STATUS[]
Optional

ExternalAuthClientProfile

External Auth client profile This configures how on-cluster, platform clients should request tokens from the identity provider.

Used by: ExternalAuthProperties.

Property Description Type
clientId External Auth client id The clientId must appear in the audience field of the TokenIssuerProfile. string
Required
component External Auth client component ExternalAuthClientComponentProfile
Required
extraScopes external auth client scopes This is useful if you have configured claim mappings that requires specific scopes to be requested beyond the standard OIDC scopes. When omitted, no additional scopes are requested. string[]
Optional
type Determines the OIDC provider client type. ExternalAuthClientType
Required

ExternalAuthClientProfile_STATUS

External Auth client profile This configures how on-cluster, platform clients should request tokens from the identity provider.

Used by: ExternalAuthProperties_STATUS.

Property Description Type
clientId External Auth client id The clientId must appear in the audience field of the TokenIssuerProfile. string
Required
component External Auth client component ExternalAuthClientComponentProfile_STATUS
Required
extraScopes external auth client scopes This is useful if you have configured claim mappings that requires specific scopes to be requested beyond the standard OIDC scopes. When omitted, no additional scopes are requested. string[]
Optional
type Determines the OIDC provider client type. ExternalAuthClientType_STATUS
Required

ExternalAuthProvisioningState_STATUS

The resource provisioning state.

Used by: ExternalAuthProperties_STATUS.

Value Description
“Accepted”
“AwaitingSecret”
“Canceled”
“Deleting”
“Failed”
“Provisioning”
“Succeeded”
“Updating”

HcpOpenShiftClusterOperatorSecrets

Used by: HcpOpenShiftClusterOperatorSpec.

Property Description Type
adminCredentials indicates where the AdminCredentials secret should be placed. If omitted, the secret will not be retrieved from Azure. genruntime.SecretDestination
Optional

HcpOpenShiftClusterProperties_CryptoRestrictions

Used by: HcpOpenShiftClusterProperties.

Value Description
“FIPS”
“None”

HcpOpenShiftClusterProperties_CryptoRestrictions_STATUS

Used by: HcpOpenShiftClusterProperties_STATUS.

Value Description
“FIPS”
“None”

ImageDigestMirror

ImageDigestMirror specifies a set of mirror registries to redirect image pulls targeting the specified source registries.

Used by: HcpOpenShiftClusterProperties.

Property Description Type
mirrors mirrors is zero or more locations that may also contain the same images. No mirror will be configured if not specified. Images can be pulled from these mirrors only if they are referenced by their digests. The mirrored location is obtained by replacing the part of the input reference that matches source by the mirrors entry, e.g. for registry.redhat.io/product/repo reference, a (source, mirror) pair *.redhat.io, mirror.local/redhat causes a mirror.local/redhat/product/repo repository to be used. The order of mirrors in this list is treated as the user’s desired priority, while source is by default considered lower priority than all mirrors. If no mirror is specified or all image pulls from the mirror list fail, the image will continue to be pulled from the repository in the pull spec. Other cluster configuration, including (but not limited to) other imageDigestMirrors objects, may impact the exact order mirrors are contacted in, or some mirrors may be contacted in parallel, so this should be considered a preference rather than a guarantee of ordering. mirrors uses one of the following formats:
  • host[:port]
  • host[:port]/namespace[/namespace…]
  • host[:port]/namespace[/namespace…]/repo

for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository[]
Required| | source| source matches the repository that users refer to, e.g. in image pull specifications. Setting source to a registry hostname, e.g. docker.io, quay.io, or registry.redhat.io, will match the image pull specification of the corresponding registry. source uses one of the following formats:

  • host[:port]
  • host[:port]/namespace[/namespace…]
  • host[:port]/namespace[/namespace…]/repo
  • [*.]host

for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository
Required|

ImageDigestMirror_STATUS

ImageDigestMirror specifies a set of mirror registries to redirect image pulls targeting the specified source registries.

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
mirrors mirrors is zero or more locations that may also contain the same images. No mirror will be configured if not specified. Images can be pulled from these mirrors only if they are referenced by their digests. The mirrored location is obtained by replacing the part of the input reference that matches source by the mirrors entry, e.g. for registry.redhat.io/product/repo reference, a (source, mirror) pair *.redhat.io, mirror.local/redhat causes a mirror.local/redhat/product/repo repository to be used. The order of mirrors in this list is treated as the user’s desired priority, while source is by default considered lower priority than all mirrors. If no mirror is specified or all image pulls from the mirror list fail, the image will continue to be pulled from the repository in the pull spec. Other cluster configuration, including (but not limited to) other imageDigestMirrors objects, may impact the exact order mirrors are contacted in, or some mirrors may be contacted in parallel, so this should be considered a preference rather than a guarantee of ordering. mirrors uses one of the following formats:
  • host[:port]
  • host[:port]/namespace[/namespace…]
  • host[:port]/namespace[/namespace…]/repo

for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository_STATUS[]
Required| | source| source matches the repository that users refer to, e.g. in image pull specifications. Setting source to a registry hostname, e.g. docker.io, quay.io, or registry.redhat.io, will match the image pull specification of the corresponding registry. source uses one of the following formats:

  • host[:port]
  • host[:port]/namespace[/namespace…]
  • host[:port]/namespace[/namespace…]/repo
  • [*.]host

for more information about the format, see: https://github.com/containers/image/blob/main/docs/containers-registries.conf.5.md#choosing-a-registry-toml-table| ImageRepository_STATUS
Required|

IngressProfile

Information about the Ingress of a cluster.

Used by: HcpOpenShiftClusterProperties.

Property Description Type
type The type of the default cluster ingress. IngressProfile_Type
Optional

IngressProfile_STATUS

Information about the Ingress of a cluster.

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
type The type of the default cluster ingress. IngressProfile_Type_STATUS
Optional

Label

Label represents the Kubernetes label

Used by: NodePoolProperties.

Property Description Type
key The key of the label string
Required
value The value of the label string
Optional

Label_STATUS

Label represents the Kubernetes label

Used by: NodePoolProperties_STATUS.

Property Description Type
key The key of the label string
Optional
value The value of the label string
Optional

ManagedServiceIdentityType

Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed).

Used by: ManagedServiceIdentity.

Value Description
“None”
“SystemAssigned”
“SystemAssigned,UserAssigned”
“UserAssigned”

ManagedServiceIdentityType_STATUS

Type of managed service identity (where both SystemAssigned and UserAssigned types are allowed).

Used by: ManagedServiceIdentity_STATUS.

Value Description
“None”
“SystemAssigned”
“SystemAssigned,UserAssigned”
“UserAssigned”

NetworkProfile

OpenShift networking configuration

Used by: HcpOpenShiftClusterProperties.

Property Description Type
hostPrefix Network host prefix int
Optional
machineCidr The CIDR block from which to assign machine IP addresses string
Optional
networkType The main controller responsible for rendering the core networking components NetworkProfile_NetworkType
Optional
podCidr The CIDR of the pod IP addresses string
Optional
serviceCidr The CIDR block for assigned service IPs string
Optional

NetworkProfile_STATUS

OpenShift networking configuration

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
hostPrefix Network host prefix int
Optional
machineCidr The CIDR block from which to assign machine IP addresses string
Optional
networkType The main controller responsible for rendering the core networking components NetworkProfile_NetworkType_STATUS
Optional
podCidr The CIDR of the pod IP addresses string
Optional
serviceCidr The CIDR block for assigned service IPs string
Optional

NodePoolAutoScaling

Node pool autoscaling

Used by: NodePoolProperties.

Property Description Type
max The maximum number of nodes in the node pool. Validation:
  • Minimum: 0 (must be >= min)

  • Maximum: 200 (only when availabilityZone is not specified)

  • No maximum when availabilityZone is specified| int
    Optional| | min| The minimum number of nodes in the node pool. Validation:

  • Minimum: 0

  • Maximum: 200 (only when availabilityZone is not specified)

  • No maximum when availabilityZone is specified| int
    Optional|

NodePoolAutoScaling_STATUS

Node pool autoscaling

Used by: NodePoolProperties_STATUS.

Property Description Type
max The maximum number of nodes in the node pool. Validation:
  • Minimum: 0 (must be >= min)

  • Maximum: 200 (only when availabilityZone is not specified)

  • No maximum when availabilityZone is specified| int
    Optional| | min| The minimum number of nodes in the node pool. Validation:

  • Minimum: 0

  • Maximum: 200 (only when availabilityZone is not specified)

  • No maximum when availabilityZone is specified| int
    Optional|

NodePoolPlatformProfile

Azure node pool platform configuration

Used by: NodePoolProperties.

Property Description Type
availabilityZone The availability zone for the node pool. Please read the documentation to see which regions support availability zones

NodePoolPlatformProfile_STATUS

Azure node pool platform configuration

Used by: NodePoolProperties_STATUS.

Property Description Type
availabilityZone The availability zone for the node pool. Please read the documentation to see which regions support availability zones

NodePoolVersionProfile

Versions represents an OpenShift version.

Used by: NodePoolProperties.

Property Description Type
channelGroup ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. string
Optional
id ID is the unique identifier of the version. string
Required

NodePoolVersionProfile_STATUS

Versions represents an OpenShift version.

Used by: NodePoolProperties_STATUS.

Property Description Type
channelGroup ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. string
Optional
id ID is the unique identifier of the version. string
Optional

PlatformProfile

Azure specific configuration

Used by: HcpOpenShiftClusterProperties.

Property Description Type
managedResourceGroup Resource group name to put cluster resources If not specified then a unique name is generated from the following pattern “aro-hcp-” + clusterName + “-” + UUID where clusterName means the hcpOpenShiftClusters resource name (up to 45 characters) followed by a 16-byte universally unique identifier per RFC 4122. string
Optional
networkSecurityGroupReference ResourceId for the NSG (network security group) attached to the cluster subnet Note that NSGs cannot be reused for other ARO-HCP clusters. genruntime.ResourceReference
Required
operatorsAuthentication The configuration that the operators of the cluster have to authenticate to Azure OperatorsAuthenticationProfile
Required
outboundType The core outgoing configuration PlatformProfile_OutboundType
Optional
subnetReference The Azure resource ID of the worker subnet Note that a subnet cannot be reused between ARO-HCP Clusters. genruntime.ResourceReference
Required
vnetIntegrationSubnetReference The Azure resource ID of a subnet that enables direct, private network connectivity between the hosted control plane and your cluster’s nodes. This subnet must be dedicated to ARO HCP and cannot be shared with the cluster subnet or any node pool subnets. genruntime.ResourceReference
Required

PlatformProfile_STATUS

Azure specific configuration

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
issuerUrl URL for the OIDC provider to be used for authentication to authenticate against user Azure cloud account string
Optional
managedResourceGroup Resource group name to put cluster resources If not specified then a unique name is generated from the following pattern “aro-hcp-” + clusterName + “-” + UUID where clusterName means the hcpOpenShiftClusters resource name (up to 45 characters) followed by a 16-byte universally unique identifier per RFC 4122. string
Optional
networkSecurityGroupId ResourceId for the NSG (network security group) attached to the cluster subnet Note that NSGs cannot be reused for other ARO-HCP clusters. string
Optional
operatorsAuthentication The configuration that the operators of the cluster have to authenticate to Azure OperatorsAuthenticationProfile_STATUS
Optional
outboundType The core outgoing configuration PlatformProfile_OutboundType_STATUS
Optional
subnetId The Azure resource ID of the worker subnet Note that a subnet cannot be reused between ARO-HCP Clusters. string
Optional
vnetIntegrationSubnetId The Azure resource ID of a subnet that enables direct, private network connectivity between the hosted control plane and your cluster’s nodes. This subnet must be dedicated to ARO HCP and cannot be shared with the cluster subnet or any node pool subnets. string
Optional

ProvisioningState_STATUS

The resource provisioning state.

Used by: HcpOpenShiftClusterProperties_STATUS, and NodePoolProperties_STATUS.

Value Description
“Accepted”
“Canceled”
“Deleting”
“Failed”
“Provisioning”
“Succeeded”
“Updating”

ResourceStatus_STATUS

ResourceStatus represents the observed status of the resource.

Used by: ExternalAuthProperties_STATUS, HcpOpenShiftClusterProperties_STATUS, and NodePoolProperties_STATUS.

Property Description Type
conditions The conditions on the resource Condition_STATUS[]
Optional

SystemData_CreatedByType_STATUS

Used by: SystemData_STATUS.

Value Description
“Application”
“Key”
“ManagedIdentity”
“User”

SystemData_LastModifiedByType_STATUS

Used by: SystemData_STATUS.

Value Description
“Application”
“Key”
“ManagedIdentity”
“User”

Taint

Taint is controlling the node taint and its effects

Used by: NodePoolProperties.

Property Description Type
effect The effect of the taint Effect
Required
key The key of the taint string
Required
value The value of the taint string
Optional

Taint_STATUS

Taint is controlling the node taint and its effects

Used by: NodePoolProperties_STATUS.

Property Description Type
effect The effect of the taint Effect_STATUS
Optional
key The key of the taint string
Optional
value The value of the taint string
Optional

TokenIssuerProfile

Token issuer profile This configures how the platform interacts with the identity provider and how tokens issued from the identity provider are evaluated by the Kubernetes API server.

Used by: ExternalAuthProperties.

Property Description Type
audiences This configures the acceptable audiences the JWT token, issued by the identity provider, must be issued to. At least one of the entries must match the aud claim in the JWT token. audiences must contain at least one entry and must not exceed ten entries. string[]
Required
ca The issuer of the token Certificate bundle to use to validate server certificates for the configured URL. It must be PEM encoded and when not specified, the system trust is used. string
Optional
url This configures the URL used to issue tokens by the identity provider. The Kubernetes API server determines how authentication tokens should be handled by matching the iss claim in the JWT to the issuerURL of configured identity providers. issuerURL must use the https scheme. string
Required

TokenIssuerProfile_STATUS

Token issuer profile This configures how the platform interacts with the identity provider and how tokens issued from the identity provider are evaluated by the Kubernetes API server.

Used by: ExternalAuthProperties_STATUS.

Property Description Type
audiences This configures the acceptable audiences the JWT token, issued by the identity provider, must be issued to. At least one of the entries must match the aud claim in the JWT token. audiences must contain at least one entry and must not exceed ten entries. string[]
Optional
ca The issuer of the token Certificate bundle to use to validate server certificates for the configured URL. It must be PEM encoded and when not specified, the system trust is used. string
Optional
url This configures the URL used to issue tokens by the identity provider. The Kubernetes API server determines how authentication tokens should be handled by matching the iss claim in the JWT to the issuerURL of configured identity providers. issuerURL must use the https scheme. string
Optional

UserAssignedIdentity_STATUS

User assigned identity properties

Used by: ManagedServiceIdentity_STATUS.

Property Description Type
clientId The client ID of the assigned identity. string
Optional
principalId The principal ID of the assigned identity. string
Optional

UserAssignedIdentityDetails

Information about the user assigned identity for the resource

Used by: ManagedServiceIdentity.

Property Description Type
reference genruntime.ResourceReference
Optional

VersionProfile

Versions represents an OpenShift version.

Used by: HcpOpenShiftClusterProperties.

Property Description Type
channelGroup ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. string
Optional
id ID is the desired X.Y version of the cluster control plane. string
Required

VersionProfile_STATUS

Versions represents an OpenShift version.

Used by: HcpOpenShiftClusterProperties_STATUS.

Property Description Type
channelGroup ChannelGroup is the name of the set to which this version belongs. Each version belongs to only a single set. If not specified, the default value is stable. string
Optional
id ID is the desired X.Y version of the cluster control plane. string
Optional

ApiProfile_Visibility

Used by: ApiProfile.

Value Description
“Private”
“Public”

ApiProfile_Visibility_STATUS

Used by: ApiProfile_STATUS.

Value Description
“Private”
“Public”

ClusterImageRegistryProfile_State

Used by: ClusterImageRegistryProfile.

Value Description
“Disabled”
“Enabled”

ClusterImageRegistryProfile_State_STATUS

Used by: ClusterImageRegistryProfile_STATUS.

Value Description
“Disabled”
“Enabled”

Condition_STATUS

Condition represents an observation of a resource’s state.

Used by: ResourceStatus_STATUS.

Property Description Type
lastTransitionTime The last time the condition transitioned from one status to another. string
Required
message A human readable message indicating details about the transition. This may be an empty string. string
Required
reason A programmatic identifier indicating the reason for the condition’s last transition. This value should be a CamelCase string. string
Required
status The status of the condition. StatusType_STATUS
Required
type Type of the condition. This is a PascalCase identifier representing the type of the condition. ConditionType_STATUS
Required

Effect

The taint effect the same as in Kubernetes

Used by: Taint.

Value Description
“NoExecute”
“NoSchedule”
“PreferNoSchedule”

Effect_STATUS

The taint effect the same as in Kubernetes

Used by: Taint_STATUS.

Value Description
“NoExecute”
“NoSchedule”
“PreferNoSchedule”

EtcdDataEncryptionProfile

The ETCD data encryption settings.

Used by: EtcdProfile.

Property Description Type
customerManaged Specify customer managed encryption key details. Required when keyManagementMode is “CustomerManaged”. CustomerManagedEncryptionProfile
Optional
keyManagementMode Specify the key management strategy used for the encryption key that encrypts the ETCD data. EtcdDataEncryptionKeyManagementModeType
Required

EtcdDataEncryptionProfile_STATUS

The ETCD data encryption settings.

Used by: EtcdProfile_STATUS.

Property Description Type
customerManaged Specify customer managed encryption key details. Required when keyManagementMode is “CustomerManaged”. CustomerManagedEncryptionProfile_STATUS
Optional
keyManagementMode Specify the key management strategy used for the encryption key that encrypts the ETCD data. EtcdDataEncryptionKeyManagementModeType_STATUS
Optional

ExternalAuthClientComponentProfile

External Auth component profile Must have unique namespace/name pairs.

Used by: ExternalAuthClientProfile.

Property Description Type
authClientNamespace The namespace of the external Auth client This specifies the namespace in which the platform component being configured to use the identity provider as an authentication mode is running. It is used in combination with name as a unique identifier. string
Required
name The name of the external auth client This specifies the name of the platform component being configured to use the identity provider as an authentication mode. It is used in combination with namespace as a unique identifier. string
Required

ExternalAuthClientComponentProfile_STATUS

External Auth component profile Must have unique namespace/name pairs.

Used by: ExternalAuthClientProfile_STATUS.

Property Description Type
authClientNamespace The namespace of the external Auth client This specifies the namespace in which the platform component being configured to use the identity provider as an authentication mode is running. It is used in combination with name as a unique identifier. string
Required
name The name of the external auth client This specifies the name of the platform component being configured to use the identity provider as an authentication mode. It is used in combination with namespace as a unique identifier. string
Required

ExternalAuthClientType

Representation of the possible values of an external authentication client’s type

Used by: ExternalAuthClientProfile.

Value Description
“Confidential”
“Public”

ExternalAuthClientType_STATUS

Representation of the possible values of an external authentication client’s type

Used by: ExternalAuthClientProfile_STATUS.

Value Description
“Confidential”
“Public”

ImageRepository

Used by: ImageDigestMirror, and ImageDigestMirror.

ImageRepository_STATUS

Used by: ImageDigestMirror_STATUS, and ImageDigestMirror_STATUS.

IngressProfile_Type

Used by: IngressProfile.

Value Description
“Disabled”
“Private”
“Public”

IngressProfile_Type_STATUS

Used by: IngressProfile_STATUS.

Value Description
“Disabled”
“Private”
“Public”

NetworkProfile_NetworkType

Used by: NetworkProfile.

Value Description
“OVNKubernetes”
“Other”

NetworkProfile_NetworkType_STATUS

Used by: NetworkProfile_STATUS.

Value Description
“OVNKubernetes”
“Other”

OperatorsAuthenticationProfile

The configuration that the operators of the cluster have to authenticate to Azure.

Used by: PlatformProfile.

Property Description Type
userAssignedIdentities Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities UserAssignedIdentitiesProfile
Required

OperatorsAuthenticationProfile_STATUS

The configuration that the operators of the cluster have to authenticate to Azure.

Used by: PlatformProfile_STATUS.

Property Description Type
userAssignedIdentities Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities UserAssignedIdentitiesProfile_STATUS
Optional

OsDiskProfile

The settings and configuration options for OSDisk

Used by: NodePoolPlatformProfile.

Property Description Type
diskStorageAccountType The type of the disk storage account

OsDiskProfile_STATUS

The settings and configuration options for OSDisk

Used by: NodePoolPlatformProfile_STATUS.

Property Description Type
diskStorageAccountType The type of the disk storage account

PlatformProfile_OutboundType

Used by: PlatformProfile.

Value Description
“LoadBalancer”

PlatformProfile_OutboundType_STATUS

Used by: PlatformProfile_STATUS.

Value Description
“LoadBalancer”

TokenClaimMappingsProfile

External Auth claim mappings profile. At a minimum username or groups must be defined.

Used by: ExternalAuthClaimProfile.

Property Description Type
groups The claim mappings groups. GroupClaimProfile
Optional
username The claim mappings username. UsernameClaimProfile
Required

TokenClaimMappingsProfile_STATUS

External Auth claim mappings profile. At a minimum username or groups must be defined.

Used by: ExternalAuthClaimProfile_STATUS.

Property Description Type
groups The claim mappings groups. GroupClaimProfile_STATUS
Optional
username The claim mappings username. UsernameClaimProfile_STATUS
Optional

TokenClaimValidationRule

External Auth claim validation rule

Used by: ExternalAuthClaimProfile.

Property Description Type
requiredClaim The required claim rule to be applied. TokenRequiredClaim
Optional
type This configures the type of the validation rule. It defaults to “RequiredClaim” TokenClaimValidationRule_Type
Optional

TokenClaimValidationRule_STATUS

External Auth claim validation rule

Used by: ExternalAuthClaimProfile_STATUS.

Property Description Type
requiredClaim The required claim rule to be applied. TokenRequiredClaim_STATUS
Optional
type This configures the type of the validation rule. It defaults to “RequiredClaim” TokenClaimValidationRule_Type_STATUS
Optional

ConditionType_STATUS

Representation of the possible condition types.

Used by: Condition_STATUS.

Value Description
“Available”
“Degraded”
“Progressing”

CustomerManagedEncryptionProfile

Customer managed encryption key profile.

Used by: EtcdDataEncryptionProfile.

Property Description Type
encryptionType The encryption type used. By default, “KMS” is used. CustomerManagedEncryptionProfile_EncryptionType
Optional
kms The Key Management Service (KMS) encryption key details. Required when encryptionType is “KMS”. KmsEncryptionProfile
Optional

CustomerManagedEncryptionProfile_STATUS

Customer managed encryption key profile.

Used by: EtcdDataEncryptionProfile_STATUS.

Property Description Type
encryptionType The encryption type used. By default, “KMS” is used. CustomerManagedEncryptionProfile_EncryptionType_STATUS
Optional
kms The Key Management Service (KMS) encryption key details. Required when encryptionType is “KMS”. KmsEncryptionProfile_STATUS
Optional

EtcdDataEncryptionKeyManagementModeType

The encryption key management mode types supported for ETCD data encryption.

Used by: EtcdDataEncryptionProfile.

Value Description
“CustomerManaged”

EtcdDataEncryptionKeyManagementModeType_STATUS

The encryption key management mode types supported for ETCD data encryption.

Used by: EtcdDataEncryptionProfile_STATUS.

Value Description
“CustomerManaged”

GroupClaimProfile

External Auth claim profile This configures how the groups of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider. When referencing a claim, if the claim is present in the JWT token, its value must be a list of groups separated by a comma (’,’). For example - ‘“example”’ and ‘“exampleOne”, “exampleTwo”, “exampleThree”’ are valid claim values.

Used by: TokenClaimMappingsProfile.

Property Description Type
claim Claim name of the external profile string
Required
prefix Prefix for the claim external profile If this is specified prefixPolicy will be set to “Prefix” by default string
Optional

GroupClaimProfile_STATUS

External Auth claim profile This configures how the groups of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider. When referencing a claim, if the claim is present in the JWT token, its value must be a list of groups separated by a comma (’,’). For example - ‘“example”’ and ‘“exampleOne”, “exampleTwo”, “exampleThree”’ are valid claim values.

Used by: TokenClaimMappingsProfile_STATUS.

Property Description Type
claim Claim name of the external profile string
Optional
prefix Prefix for the claim external profile If this is specified prefixPolicy will be set to “Prefix” by default string
Optional

OsDiskProfile_DiskStorageAccountType

Used by: OsDiskProfile.

Value Description
“Premium_LRS”
“StandardSSD_LRS”
“Standard_LRS”

OsDiskProfile_DiskStorageAccountType_STATUS

Used by: OsDiskProfile_STATUS.

Value Description
“Premium_LRS”
“StandardSSD_LRS”
“Standard_LRS”

OsDiskProfile_DiskType

Used by: OsDiskProfile.

Value Description
“Ephemeral”
“Managed”

OsDiskProfile_DiskType_STATUS

Used by: OsDiskProfile_STATUS.

Value Description
“Ephemeral”
“Managed”

StatusType_STATUS

Representation of the possible values of a condition status.

Used by: Condition_STATUS.

Value Description
“False”
“True”
“Unknown”

TokenClaimValidationRule_Type

Used by: TokenClaimValidationRule.

Value Description
“RequiredClaim”

TokenClaimValidationRule_Type_STATUS

Used by: TokenClaimValidationRule_STATUS.

Value Description
“RequiredClaim”

TokenRequiredClaim

Token required claim validation rule.

Used by: TokenClaimValidationRule.

Property Description Type
claim Claim name for the validation profile claim is a required field that configures the name of the required claim. string
Required
requiredValue Required value requiredValue is a required field that configures the value that claim must have when taken from the incoming JWT claims. If the value in the JWT claims does not match, the token will be rejected for authentication. string
Required

TokenRequiredClaim_STATUS

Token required claim validation rule.

Used by: TokenClaimValidationRule_STATUS.

Property Description Type
claim Claim name for the validation profile claim is a required field that configures the name of the required claim. string
Optional
requiredValue Required value requiredValue is a required field that configures the value that claim must have when taken from the incoming JWT claims. If the value in the JWT claims does not match, the token will be rejected for authentication. string
Optional

UserAssignedIdentitiesProfile

Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities

Used by: OperatorsAuthenticationProfile.

Property Description Type
controlPlaneOperatorsReferences The set of Azure User-Assigned Managed Identities leveraged for the Control Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. map[string]genruntime.ResourceReference
Required
dataPlaneOperatorsReferences The set of Azure User-Assigned Managed Identities leveraged for the Data Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. map[string]genruntime.ResourceReference
Required
serviceManagedIdentityReference Represents the information associated to an Azure User-Assigned Managed Identity whose purpose is to perform service level actions. genruntime.ResourceReference
Required

UserAssignedIdentitiesProfile_STATUS

Represents the information related to Azure User-Assigned managed identities needed to perform Operators authentication based on Azure User-Assigned Managed Identities

Used by: OperatorsAuthenticationProfile_STATUS.

Property Description Type
controlPlaneOperators The set of Azure User-Assigned Managed Identities leveraged for the Control Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. map[string]string
Optional
dataPlaneOperators The set of Azure User-Assigned Managed Identities leveraged for the Data Plane operators of the cluster. The set of required managed identities is dependent on the Cluster’s OpenShift version. map[string]string
Optional
serviceManagedIdentity Represents the information associated to an Azure User-Assigned Managed Identity whose purpose is to perform service level actions. string
Optional

UsernameClaimProfile

External Auth claim profile This configures how the username of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider.

Used by: TokenClaimMappingsProfile.

Property Description Type
claim Claim name of the external profile string
Required
prefix Prefix for the claim external profile Must be set when the prefixPolicy field is set to Prefix and must be unset otherwise. string
Optional
prefixPolicy Prefix policy is an optional field that configures how a prefix should be applied to the value of the JWT claim specified in the claim field. Allowed values are Prefix, NoPrefix, and None. If not specified, the default policy is None. When set to Prefix, the value specified in the prefix field will be prepended to the value of the JWT claim. The prefix field must be set when prefixPolicy is Prefix. When set to NoPrefix, no prefix will be prepended to the value of the JWT claim. When set to None, this means no opinion and the platform is left to choose any prefixes that are applied which is subject to change over time. Currently, the platform prepends {issuerURL}# to the value of the JWT claim when the claim is not email. As an example, consider the following scenario: prefix is unset, issuerURL is set to https://myoidc.tld, the JWT claims include “username”:“userA” and “email”:“userA UsernameClaimPrefixPolicy
Optional

UsernameClaimProfile_STATUS

External Auth claim profile This configures how the username of a cluster identity should be constructed from the claims in a JWT token issued by the identity provider.

Used by: TokenClaimMappingsProfile_STATUS.

Property Description Type
claim Claim name of the external profile string
Optional
prefix Prefix for the claim external profile Must be set when the prefixPolicy field is set to Prefix and must be unset otherwise. string
Optional
prefixPolicy Prefix policy is an optional field that configures how a prefix should be applied to the value of the JWT claim specified in the claim field. Allowed values are Prefix, NoPrefix, and None. If not specified, the default policy is None. When set to Prefix, the value specified in the prefix field will be prepended to the value of the JWT claim. The prefix field must be set when prefixPolicy is Prefix. When set to NoPrefix, no prefix will be prepended to the value of the JWT claim. When set to None, this means no opinion and the platform is left to choose any prefixes that are applied which is subject to change over time. Currently, the platform prepends {issuerURL}# to the value of the JWT claim when the claim is not email. As an example, consider the following scenario: prefix is unset, issuerURL is set to https://myoidc.tld, the JWT claims include “username”:“userA” and “email”:“userA UsernameClaimPrefixPolicy_STATUS
Optional

CustomerManagedEncryptionProfile_EncryptionType

Used by: CustomerManagedEncryptionProfile.

Value Description
“KMS”

CustomerManagedEncryptionProfile_EncryptionType_STATUS

Used by: CustomerManagedEncryptionProfile_STATUS.

Value Description
“KMS”

KmsEncryptionProfile

Configure etcd encryption Key Management Service (KMS) key. Your Microsoft Entra application used to create the cluster must be authorized to access this keyvault, e.g using the AzureCLI: az keyvault set-policy -n $KEYVAULT_NAME --key-permissions decrypt encrypt --spn (YOUR APPLICATION CLIENT ID)

Used by: CustomerManagedEncryptionProfile.

Property Description Type
activeKey The details of the active key. KmsKey
Required
vaultName vaultName is the name of the keyvault that contains the secret. string
Required
visibility visibility of the keyvault that contains the secret. KeyVaultVisibility
Required

KmsEncryptionProfile_STATUS

Configure etcd encryption Key Management Service (KMS) key. Your Microsoft Entra application used to create the cluster must be authorized to access this keyvault, e.g using the AzureCLI: az keyvault set-policy -n $KEYVAULT_NAME --key-permissions decrypt encrypt --spn (YOUR APPLICATION CLIENT ID)

Used by: CustomerManagedEncryptionProfile_STATUS.

Property Description Type
activeKey The details of the active key. KmsKey_STATUS
Optional
vaultName vaultName is the name of the keyvault that contains the secret. string
Optional
visibility visibility of the keyvault that contains the secret. KeyVaultVisibility_STATUS
Optional

UsernameClaimPrefixPolicy

UsernameClaimPrefixPolicy configures whether to add a prefix to a JWT claim.

Used by: UsernameClaimProfile.

Value Description
“NoPrefix”
“None”
“Prefix”

UsernameClaimPrefixPolicy_STATUS

UsernameClaimPrefixPolicy configures whether to add a prefix to a JWT claim.

Used by: UsernameClaimProfile_STATUS.

Value Description
“NoPrefix”
“None”
“Prefix”

KeyVaultVisibility

The internet visibility of a keyvault resource

Used by: KmsEncryptionProfile.

Value Description
“Private”
“Public”

KeyVaultVisibility_STATUS

The internet visibility of a keyvault resource

Used by: KmsEncryptionProfile_STATUS.

Value Description
“Private”
“Public”

KmsKey

A representation of a KeyVault Secret.

Used by: KmsEncryptionProfile.

Property Description Type
name name is the name of the keyvault key used for encryption/decryption. string
Required
version version contains the version of the key to use. string
Required

KmsKey_STATUS

A representation of a KeyVault Secret.

Used by: KmsEncryptionProfile_STATUS.

Property Description Type
name name is the name of the keyvault key used for encryption/decryption. string
Optional
version version contains the version of the key to use. string
Optional